EasyManuals Logo
Home>Enterasys>Switch>SecureStack C2 C2G170-24

Enterasys SecureStack C2 C2G170-24 User Manual

Enterasys SecureStack C2 C2G170-24
698 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #501 background imageLoading...
Page #501 background image
Dynamic ARP Inspection Overview
SecureStack C2 Configuration Guide 17-17
Loopbackaddresses(intherange127.0.0.0/8)
Logging Invalid Packets
Bydefault,DAIwritesalogmessagetothenormalbufferedlogforeachinvalidARPpacketit
drops.YoucanconfigureDAItonotloginvalidpacketsforspecificVLANs.
Packet Forwarding
DAIforwardsvalidARPpacketswhosedestinationMACaddressisnotlocal.TheingressVLAN
couldbeaswitchingorroutingVLAN.ARPrequestsarefloodedintheVLAN.ARPresponsesare
unicasttowardtheirdestination.DAIqueriestheMACaddresstabletodetermin ethe outgoing
port.IfthedestinationMAC
addressislocal,DAIgivesvalidARPpacketstotheARPapplication.
Rate Limiting
ToprotecttheswitchfromDHCPattackswhenDAIisenabled,theDAIapplicationenforcesarate
limitforARPpacketsreceivedonuntrustedinterfaces.DAImonitorsthereceiverateoneach
interfaceseparately.Ifthereceiverateexceedsaconfigurablelimit,DAIerrordisablesthe
interface,whicheffectivelybringsdown
theinterface.Youcanusethesetportenablecommand
toreenabletheport.
Youcanconfigureboththerateandtheburstinterval.Thedefaultrateis15ppsoneachuntrusted
interfacewitharangeof0to100pps.Thedefaultburstintervalis1secondwith
arangeto1to15
seconds..TheratelimitcannotbesetontrustedinterfacessinceARPpacketsreceivedontrusted
interfacesdonotcometotheCPU.
Eligible Interfaces
DynamicARPinspectionisenabledperVLAN,effectivelyenablingDAIonthemembersofthe
VLAN,eitherphysicalportsorLAGs.TrustisspecifiedontheVLANmembers.
DAIcannotbeenabledonportbasedroutinginterfaces.Itmaybeconnectedto:
•Asinglehostthroughatrustedlink(forexample,
aserver)
•Ifmultiplehostsneedtoconnected,theremustbeaswitchbetweentherouterandthehosts,
withDAIenabledonthatswitch
Interaction with Other Functions
•DAIreliesontheDHCPsnoopingapplicationtoverifythata{IPaddress,MACaddress,
VLAN,interface}tupleisvalid.
•DAIregisterswithdot1qtoreceivenotificationofVLANmembershipchangesfortheVLANs
whereDAIisenabled.
•DAItellsthedriverabouteachuntrustedinterface(physicalportorLAG)where
DAIis
enabledsothatthehardwarewillint erceptARPpacketsand sendthemtotheCPU.

Table of Contents

Other manuals for Enterasys SecureStack C2 C2G170-24

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Enterasys SecureStack C2 C2G170-24 and is the answer not in the manual?

Enterasys SecureStack C2 C2G170-24 Specifications

General IconGeneral
BrandEnterasys
ModelSecureStack C2 C2G170-24
CategorySwitch
LanguageEnglish

Related product manuals